Jobs · Engineering · Illinois

Senior Manual Ethical Hacker

Bank of America · Chicago, IL · 1 wk ago
EngineeringFull-time

Key Responsibilities

  • Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
  • Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
  • Develop Proof-of-concepts for exploitation.
  • Assess the security, effectiveness, and practicality of multiple technology systems.
  • Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
  • Prepare and present detailed technical information for various media including documents, reports, and notifications.
  • Provide clear and practical advice regarding managing risks.
  • Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
  • Respond to security incidents and provide technical assistance to leadership across the Information Security organization.

Required Skills

  • Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment.
  • Detailed technical knowledge in at least 5 of the following areas: security engineering, application architecture, authentication and security protocols, application session management, applied cryptography, common communication protocols, mobile frameworks, single sign-on technologies, exploit automation platforms, Web APIs, cloud environments, LLM security, mobile application analysis.
  • Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings.
  • Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools.
  • Experience performing manual code reviews for security relevant issues.
  • Experience working with DAST and SAST tools to identify vulnerabilities.
  • Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies).
  • Experience with vulnerability assessment tools and penetration testing techniques.
  • Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction.
  • Threat Analysis, threat modelling and SBOM analysis.
  • Innovative thinking, threat actor simulation.
  • Technology Systems Assessment.
  • Technical Documentation.
  • Adaptability.
  • Collaboration.
  • Scenario Planning and Analysis.
  • Test Engineering.
  • Written Communications.
  • Attention to Detail.
  • Information Systems Management.
  • Issue Management.
  • Presentation Skills.

Desired

  • CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]
  • Strong programming/scripting skills.
  • Frida
  • Binary analysis (disassembly skills)

Similar jobs